← Regulations / New Zealand / Operating Models / Crypto debit card

Crypto-funded debit card in New Zealand

A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.

Conditional AI-Generated · Unreviewed

Crypto debit card is conditionally permitted in New Zealand with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • Register as a reporting entity with the Department of Internal Affairs (DIA) under the AML/CFT Act 2009 (nz.licensing.primary-requirement-amlcft-reporting-entity)
  • Conduct a comprehensive risk assessment specific to the business, customers, products, services, and jurisdictions (nz.aml.conduct-a-comprehensive-risk-assessment)
  • Establish and maintain an AML/CFT programme covering policies, procedures, and controls to detect, deter, and report suspicious activities (nz.aml.establish-and-maintain-an-amlcft)
  • Perform standard customer due diligence (CDD) including identity verification (full name, date of birth, address) and beneficial ownership identification (>25% threshold) (nz.aml.identity-verification-obtaining-and-verifying)
  • Apply enhanced CDD for PEPs, high-risk countries, complex/unusually large transactions, and complex ownership structures — requires senior management approval and source-of-funds/wealth verification (nz.aml.enhanced-cdd-ecdd-required-for)
  • Screen customers and transactions against UN and other sanctions lists (nz.aml.sanctions-screening-screening-customers-and)
  • Report suspicious transactions or activities to the New Zealand Police Financial Intelligence Unit (FIU) (nz.aml.obligation-to-report-vasps-must)
  • Comply with the Identity Verification Code of Practice, including specific requirements for non-face-to-face onboarding (e.g., video conferencing or biometric verification) (nz.aml.face-to-face-vs-non-face-to-face-specific-requirements)
  • Maintain ongoing monitoring of transactions and customer information (nz.aml.ongoing-monitoring-regularly-reviewing-transactions)
  • No tipping-off prohibition — cannot disclose to customer or third party that a report has been made (nz.aml.no-tipping-off-reporting-entities)

Key Restrictions

  • The operator must register as a reporting entity with DIA under the AML/CFT Act 2009 for the exchange of virtual assets for fiat currency (the off-ramp/crypto-to-fiat conversion) (nz.licensing.businesses-that-exchange-virtual-assets)
  • If the operator also provides custodial safekeeping of customer crypto (e.g., holding private keys for card top-up wallets), it must register as a reporting entity on that basis too (nz.licensing.businesses-that-offer-safekeeping-services)
  • The crypto-to-fiat conversion at point of sale or top-up constitutes a 'money or value transfer service' under the AML/CFT Act (nz.licensing.businesses-that-transmit-money-or)
  • If the operator issues e-money redeemable for fiat or accepts fiat deposits from the public, it may fall under the RBNZ's Non-Bank Deposit Taker (NBDT) regime, requiring NBDT registration with significant capital requirements (nz.licensing.if-the-payment-processor-also)
  • Potential secondary FSP registration/licensing with the FMA if the service is deemed a 'financial service' under the FSP Act 2008 — e.g., operating a scheme that involves client fund management (nz.licensing.potential-secondary-requirement-fsp-registrationlicensing)
  • No specific minimum capital under AML/CFT Act alone, but if FMA licensing or RBNZ NBDT licensing is triggered, significant capital and solvency requirements apply (nz.licensing.however-if-an-fma-license, nz.licensing.rbnz-nbdt-licensing-has-significant)
  • The operator needs a partner-bank or BIN-sponsor arrangement to issue cards on a card scheme (e.g., Mastercard, Visa) — no specific NZ regulatory fact addresses this directly, but it is an operational necessity

Key Risks

  • DIA enforcement precedent: Coinstash and Dasset were fined NZD $2.3 million and NZD $2.5 million respectively for AML/CFT compliance failures, demonstrating significant enforcement risk for non-compliance (nz.enforcement.violation-type-significant-breaches-of, nz.enforcement.entity-targeted-dasset-limited-now)
  • Ambiguity around whether a crypto-funded debit card triggers the RBNZ NBDT regime if the operator holds fiat balances for customers — the boundary between payment processing and deposit-taking is not sharply defined for this model
  • Tax treatment creates dual taxable events: the crypto-to-fiat conversion (disposal of crypto is a taxable event per NZ tax rules) and potentially the spending itself, creating customer friction and reporting complexity (nz.tax.taxable-event-when-you-dispose)
  • IRD may treat frequent crypto-to-fiat conversions as 'in the business of dealing', making all gains taxable income rather than capital (nz.tax.frequency-and-volume-regular-high-volume, nz.tax.organisation-and-system-if-the)
  • FMA enforcement risk if the card program is structured in a way that constitutes an unregistered financial service or unlicensed financial advice (nz.enforcement.entity-targeted-james-malcolm-allan)

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

Businesses that exchange virtual assets for fiat currency, other virtual assets, or facilitate such exchanges are deemed "reporting entities" under the AML/CFT Act. This includes operating a trading platform.

licensing 60% confidence

Businesses that offer safekeeping services for virtual assets on behalf of customers (i.e., holding private keys or managing custodial wallets) are considered "reporting entities" under the AML/CFT Act.

licensing 60% confidence

Businesses that transmit money or value using virtual assets, or facilitate payments in VAs, are typically classified as "money or value transfer services" under the AML/CFT Act and must register with the DIA.

licensing 60% confidence

Potential Secondary Requirement: Non-Bank Deposit Taker (NBDT) Registration (RBNZ) / FSP Licensing (FMA)

licensing 60% confidence

However, if an FMA license is triggered (e.g., Financial Advice Provider, Market Services Licence), then specific capital and solvency requirements will apply, often based on the nature and scale of the financial services provided. For example, FAPs must demonstrate adequate financial resources.

licensing 60% confidence

There are no specific minimum capital requirements under the AML/CFT Act for VASPs solely registered as reporting entities.

licensing 60% confidence

AML/CFT Registration (DIA): Most crypto businesses, including exchanges, custody providers, and payment processors dealing with VAs, are categorised as "reporting entities" under the AML/CFT Act. This requires them to register with the DIA as a reporting entity and comply with comprehensive AML/CFT obligations. This is not a "license" in the traditional sense of permitting operation, but a mandatory registration for AML/CFT compliance.

aml 20% confidence

Conduct a comprehensive risk assessment: This identifies and assesses the money laundering and terrorism financing risks specific to their business, customers, products, services, delivery channels, and jurisdictions they operate in. Risks associated with the inherent characteristics of virtual assets (e.g., pseudo-anonymity, speed of transfer, global reach) must be specifically addressed.

aml 20% confidence

Establish and maintain an AML/CFT Programme: This is a documented programme that outlines the policies, procedures, and controls the VASP has in place to mitigate the risks identified in their risk assessment. It must include measures to:

aml 20% confidence

Identity Verification: Obtaining and verifying the customer's full name, date of birth, and address using reliable and independent sources (e.g., passport, driver's license, national ID, proof of address utility bills). For legal entities, verifying the entity's name, legal form, proof of existence, registered address, and articles of association.

aml 20% confidence

Enhanced CDD (ECDD): Required for higher-risk situations, such as:

aml 20% confidence

Sanctions Screening: Screening customers and transactions against relevant sanctions lists (e.g., UN Security Council sanctions lists).

aml 20% confidence

Obligation to Report: VASPs must report any transaction or activity they suspect is related to money laundering, terrorism financing, or other criminal activity to the New Zealand Police Financial Intelligence Unit (FIU).

aml 20% confidence

Face-to-Face vs. Non-Face-to-Face: Specific requirements apply to non-face-to-face onboarding to mitigate higher risks. Technologies like video conferencing or biometric verification can be used if they meet the standards set out in the Identity Verification Code of Practice.

aml 20% confidence

Ongoing Monitoring: Regularly reviewing transactions and customer information to ensure it is consistent with the VASP's knowledge of the customer, their business, and risk profile. This is crucial for VASPs given the dynamic nature of virtual assets.

aml 20% confidence

No Tipping Off: Reporting entities are prohibited from disclosing to the customer or any third party that a report has been made or that an investigation is underway.

enforcement 70% confidence

Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, suspicious transaction reporting, and compliance programme. Penalty Amount: NZD $2.3 million. Outcome: Coinstash admitted to the breaches and agreed to pay the penalty. The DIA noted this was the largest financial penalty issued under the AML/CFT Act for a single infringement notice.

enforcement 70% confidence

Entity Targeted: Dasset Limited (now in liquidation). Violation Type: Significant breaches of the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), including failures in customer due diligence, risk assessments, record-keeping, and the overall compliance programme. Penalty Amount: NZD $1 million. Outcome: Dasset admitted to the breaches and agreed to pay the penalty. The company subsequently went into liquidation in October 2023, though the DIA noted the penalty was not the direct cause.

enforcement 70% confidence

Entity Targeted: James Malcolm Allan (individual). Violation Type: Operating an unregistered financial service provider, making misleading representations about financial products (including crypto-assets), and breaches of the Fair Trading Act 1986 and the Financial Service Providers (Registration and Dispute Resolution) Act 2008. Allan had been promoting investments via social media, purporting to offer high returns from trading shares and crypto-assets. Penalty Amount: Permanent ban from providing financial services and from acting as a director or manager of any financial service provider. A pecuniary penalty of NZD $50,000 was also ordered. Outcome: The FMA successfully obtained orders from the High Court against Allan, resulting in the ban and penalty. This was a significant action against an individual promoting crypto-related investments without proper registration or disclosure.

tax 60% confidence

Taxable Event: When you dispose of cryptocurrency (sell it for fiat, trade it for another crypto, or use it to buy goods/services), it's a taxable event.

tax 60% confidence

Frequency and Volume: Regular, high-volume trading activities are strong indicators of being "in the business of dealing" or engaging in a "scheme for profit," making gains taxable.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a crypto-funded debit card can be offered in New Zealand, but the operator must register as a DIA reporting entity under the AML/CFT Act 2009 for the crypto-to-fiat exchange and any custodial wallet services, and may require additional FMA licensing or RBNZ NBDT registration depending on whether fiat balances are held or e-money is issued; a local entity is required.

Questions this verdict aims to answer

  • What e-money / payment-institution license is required?
  • How is the crypto-to-fiat conversion regulated?
  • What KYC and AML obligations apply to cardholders?
  • What partner-bank or BIN-sponsor arrangements are required?